closing security gap [ignore guarding change for now]
This commit is contained in:
@@ -5,8 +5,9 @@
|
||||
|
||||
require_role($user_role, ['owner', 'admin']);
|
||||
|
||||
// ─── Allowed upload MIME types ────────────────────────────────────────────
|
||||
// ─── Allowed upload types ─────────────────────────────────────────────────
|
||||
const ALLOWED_MIME = ['image/jpeg', 'image/png', 'image/gif', 'image/webp'];
|
||||
const ALLOWED_EXT = ['jpg', 'jpeg', 'png', 'gif', 'webp'];
|
||||
const MAX_SIZE = 2 * 1024 * 1024; // 2 MB
|
||||
|
||||
// ─── Helper: handle one image slot ────────────────────────────────────────
|
||||
@@ -48,13 +49,17 @@
|
||||
throw new RuntimeException('Invalid file type. Only JPEG, PNG, GIF, WEBP allowed.');
|
||||
}
|
||||
|
||||
$ext = strtolower(pathinfo($file['name'], PATHINFO_EXTENSION));
|
||||
if (!in_array($ext, ALLOWED_EXT, true)) {
|
||||
throw new RuntimeException('Invalid file extension. Only jpg, png, gif, webp allowed.');
|
||||
}
|
||||
|
||||
// Delete old file first
|
||||
if ($current && file_exists($upload_dir . $current)) {
|
||||
unlink($upload_dir . $current);
|
||||
}
|
||||
|
||||
$ext = pathinfo($file['name'], PATHINFO_EXTENSION);
|
||||
$filename = $prefix . uniqid() . '.' . strtolower($ext);
|
||||
$filename = $prefix . uniqid() . '.' . $ext;
|
||||
|
||||
if (!move_uploaded_file($file['tmp_name'], $upload_dir . $filename)) {
|
||||
throw new RuntimeException("Failed to save {$slot}.");
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
<?php
|
||||
session_start();
|
||||
define('UNAUTHENTICATED_ROUTE', true);
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
require '../../../assets/utils/classes/PasswordResetManager.php';
|
||||
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
<?php
|
||||
session_start();
|
||||
define('UNAUTHENTICATED_ROUTE', true);
|
||||
require '../../../assets/utils/db_auth.php';
|
||||
require '../../../assets/utils/classes/PasswordResetManager.php';
|
||||
|
||||
|
||||
Reference in New Issue
Block a user